All Apps and Add-ons

Deleting a file after calling splunkforwarder add oneshot

othersider2
New Member

After calling splunk/forwarder/bin/splunk add oneshot , is it ok to delete the file I just added, or does the file need to be kept on disk for the forwarder to give it to the splunk enterprise server receiver?

0 Karma

inventsekar
SplunkTrust
SplunkTrust

After calling splunk/forwarder/bin/splunk add oneshot , it is ok to delete the file. maybe, make sure the file got ingested(on splunk gui, you can run the search query for the file)

https://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorfilesanddirectoriesusingtheCLI

Copy the file directly into Splunk. This uploads the file once, but Splunk Enterprise does not continue to monitor it.
You cannot use the oneshot command against a remote Splunk Enterprise instance. You also cannot use the command with either recursive folders or wildcards as a source. Specify the exact source path of the file you want to monitor.

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

p_gurav
Champion

I am not sure about oneshot, but you can try batch input for your requirement.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...